<Vulnerability name="CVE-2026-70652">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Moderate</ThreatSeverity>
    <PublicDate>2026-08-20T21:04:51</PublicDate>
    <Bugzilla id="2520799" url="https://bugzilla.redhat.com/show_bug.cgi?id=2520799" xml:lang="en:us">
libvips: libvips: Information disclosure or denial of service via heap buffer over-read when processing JPEGs with gain maps
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>5.0</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:H</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-125</CWE>
    <Details xml:lang="en:us" source="Mitre">
libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, libvips built with libultrahdr support can incorrectly size an output buffer in libvips/foreign/uhdrsave.c within vips_foreign_save_uhdr_set_raw_hdr when a pipeline enlarges an incoming JPEG to a very large output before encoding a gain map through VipsForeignSaveUhdr. The undersized allocation can cause a heap buffer over-read that may disclose adjacent data or crash the process. This issue is fixed in version 8.18.3.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in libvips, an image processing library. When libvips is built with libultrahdr support, it can incorrectly size an output buffer during the process of enlarging an incoming JPEG to a very large output before encoding a gain map. This undersized allocation can lead to a heap buffer over-read, potentially disclosing adjacent memory data or causing the application to crash, resulting in a denial of service.
    </Details>
    <Statement xml:lang="en:us">
Moderate: This flaw in libvips, when built with libultrahdr support, could lead to information disclosure or a denial of service. Exploitation requires processing a specially crafted JPEG with gain map data, which may not be a default or common operation in all Red Hat environments. The impact is limited to the application processing the malicious image.
    </Statement>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-70652
https://nvd.nist.gov/vuln/detail/CVE-2026-70652
https://github.com/libvips/libvips/commit/cff17794f0698a4f47c74bb31c9700b2c83252a8
https://github.com/libvips/libvips/pull/5039
https://github.com/libvips/libvips/releases/tag/v8.18.3
https://github.com/libvips/libvips/security/advisories/GHSA-h27h-jf9v-m8rg
    </References>
</Vulnerability>